Impact
The vulnerability arises when the plugin inserts sensitive information into outgoing data, allowing attackers to retrieve embedded confidential data. This results in a loss of confidentiality, as vulnerability is classified as CWE-201, a sensitive data exposure flaw.
Affected Systems
The Tribal plugin developed by thetechtribe is affected for all releases up to and including version 1.3.4. Any WordPress website using these versions that has the plugin installed is at risk.
Risk and Exploitability
Because the issue allows the extraction of embedded sensitive data, an attacker who can trigger data sending through the plugin could obtain confidential information. Severity details such as CVSS or EPSS are not provided, and the vulnerability is not listed in the CISA KEV catalog, so the exact exploitation potential is unclear. The likely attack vector is local or remote depending on how the plugin handles outgoing data, but the input does not specify a precise method.
OpenCVE Enrichment